the wire · #topnews · 2026-09-13
Terabytes of credentials leaked in massive supply-chain attack
Cech This Review

The digital landscape just took a massive hit. Security firms CloudSEK and Hudson Rock revealed that terabytes of sensitive credentials were leaked in a supply-chain attack targeting LiteLLM. This open-source tool is widely used to streamline AI-driven software development, making its compromise particularly alarming for the industry. The scale of the breach is staggering, affecting some of the most powerful organizations on the planet.
Microsoft, Amazon, Cisco, Samsung, and Salesforce are among the entities whose access secrets were exposed. These are not small startups but global giants with vast digital infrastructures. The attackers gained access to cloud keys, repository tokens, SSH keys, and Kubernetes secrets. They also stole package publishing credentials and environment variables that could grant entry to over 2,500 organizations. This level of access is a nightmare for any security team.
The extraction happened during a narrow forty-minute window in March. Victims used compromised versions of LiteLLM downloaded from the official Python Package Index repository. This detail is crucial because it shows how even trusted sources can be weaponized. The attackers did not need to break in through a backdoor. They simply poisoned the well that developers drink from daily.
Hudson Rock made the discovery after analyzing a massive 195TB file. This sheer volume of data suggests a deep and persistent intrusion. Neither firm has identified the source of the information yet. The anonymity of the attacker adds to the uncertainty and fear surrounding this event. It remains unclear if this was a targeted strike or a broad opportunistic sweep.
This incident serves as a stark warning for the AI development community. Open-source tools are the backbone of modern software engineering. When these tools are compromised, the ripple effects are immediate and widespread. Developers often trust these libraries implicitly. They rarely inspect the code for hidden malicious payloads. This trust is what makes supply-chain attacks so effective.
The implications for AI security are profound. As more companies integrate AI into their workflows, the attack surface expands. LiteLLM acts as a bridge between different AI providers. Compromising it gives attackers a master key to multiple systems. This is not just about stolen data. It is about the potential for long-term espionage or sabotage. The risk extends far beyond the initial leak.
What this means for you is that you must audit your dependencies immediately. If you use LiteLLM or similar tools, check your logs for any usage during March. Consider rotating all credentials that might have been exposed. Implement stricter monitoring for unusual API calls. You cannot afford to assume your tools are safe without verification.
Try this workflow with your AI assistant. Ask it to scan your project requirements files for any outdated or suspicious packages. Request a script that automatically rotates API keys for your cloud providers. Use the AI to generate a checklist for verifying the integrity of your installed libraries. This proactive step can save you from a catastrophic breach.
Reporting basis: original story
← back to The Wire






